Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2026-4600
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter valid…
Jsrsasign
11.1.1+
HIGH 8.1
CVE-2026-4478
A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of t…
Mitigation only
CRITICAL 9.0
CVE-2026-3564
A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to ob…
Mitigation only
HIGH 7.5
CVE-2026-4258
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation…
Stanford Javascript Crypto Library
after 1.0.8
CRITICAL 9.1
CVE-2026-27962
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's …
Authlib
1.6.9+
HIGH 8.8
CVE-2026-3562
Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to…
Hue Bridge V2 Firmware
1975170000+
HIGH 7.5
CVE-2026-32614
Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2…
No fix yet
MEDIUM 5.5
CVE-2026-21002
Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.
Galaxy Store
4.6.03.8+
CRITICAL 9.8
CVE-2026-20997
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authenticat…
Smart Switch
3.7.69.15+
CRITICAL 9.8
CVE-2025-52648
HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tamp…
Aion
2.1.2+
HIGH 7.5
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515…
Pyjwt
2.12.0+
HIGH 7.5
CVE-2026-28432
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP …
Misskey
2026.3.1+
HIGH 7.2
CVE-2025-41767
A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in …
Universal Bacnet Router Firmware
6.0.1.0+
CRITICAL 9.8
CVE-2026-28802
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passi…
Authlib
1.6.7+
CRITICAL 9.1
CVE-2026-29000EPSS 6%
pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs…
Mitigation only
MEDIUM 5.3
CVE-2026-2746
SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect …
Seppmail
15.0.1+
MEDIUM 5.3
CVE-2026-27445
SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the expected key, allowing signatu…
Seppmail
15.0.1+
MEDIUM 5.9
CVE-2025-15598
A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.…
Sqlbot
after 1.5.1
HIGH 7.5
CVE-2026-3338
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objec…
Aws Lc Sys
0.38.0 / 1.69.0+
HIGH 7.5
CVE-2026-22866
Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `…
Ethereum Name Service
after 1.6.2
MEDIUM 6.7
CVE-2025-32060
The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to add…
Mitigation only
HIGH 8.8
CVE-2026-25922
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Asser…
Authentik
2025.8.6 / 2025.10.4+
HIGH 8.8
CVE-2026-23687
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …
Sap Basis
Mitigation only
HIGH 8.1
CVE-2026-1529
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invita…
Mitigation only
HIGH 8.1
CVE-2026-25793
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration)…
Nebula
1.10.3+
CRITICAL 9.6
CVE-2026-1568
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allo…
Mitigation only
HIGH 7.5
CVE-2026-0750
Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication B…
Commerce Paybox
after 7.x-1.5
MEDIUM 5.3
CVE-2026-24850
The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to ver…
Patch available
MEDIUM 5.5
CVE-2025-15469
Issue summary: The 'openssl dgst' command-line tool silently truncates input
data to 16MB when using one-shot signing algorithms and reports success …
OpenSSL
3.5.5 / 3.6.1+
MEDIUM 5.3
CVE-2026-24807
Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/b…
Patch available